PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13844 Schneider Electric CVE debrief

CVE-2025-13844 is a user-assisted double-free vulnerability in Schneider Electric EcoStruxure Power Build Rapsody that may lead to heap memory corruption when an end user imports a malicious SSD project file shared by an attacker. Schneider Electric and CISA rate the issue as Medium, and the advisory provides fixed releases plus temporary handling guidance for environments that cannot patch immediately.

Vendor
Schneider Electric
Product
EcoStruxure Power Build Rapsody software
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-15
Original CVE updated
2026-09-03
Advisory published
2026-01-15
Advisory updated
2026-09-03

Who should care

Organizations using EcoStruxure Power Build Rapsody, especially engineering, operations, and security teams that exchange SSD project files with partners, contractors, or other external sources. This is most relevant where users routinely open third-party project files on systems running affected Rapsody versions.

Technical summary

The advisory describes a double-free condition in Rapsody’s handling of imported SSD project files. Successful triggering requires user interaction: an end user must import a malicious project file into the application. The stated impact is heap memory corruption; the supplied advisory text assigns a Medium severity and a local/user-assisted attack profile.

Defensive priority

Medium. Patch promptly if Rapsody is used to import externally sourced project files, and raise priority further in environments where file exchange is common or tightly coupled to engineering workflows.

Recommended defensive actions

  • Install a fixed version of EcoStruxure Power Build Rapsody: FR V2.8.1.0401, INT V2.8.6.200, or ES V2.8.5.0301, as applicable.
  • For Belgian releases, use BEL(NL) V2.8.3.0201 or BEL(FR) V2.8.8.0201 and contact Schneider Electric Customer Care Center for assistance if needed.
  • Restart the service after installing the updated version.
  • If patching is delayed, only open projects from trusted sources.
  • Scan externally created project files for malware before opening them.
  • Review and apply CISA ICS recommended practices and defense-in-depth guidance for layered protection around engineering workstations and file exchange workflows.

Evidence notes

The CISA CSAF advisory (ICSA-26-015-10) and Schneider Electric SEVD-2026-013-04 materials both state that a malicious SSD project file can trigger a double-free leading to heap memory corruption in Rapsody. The remediation section lists fixed versions and explicitly notes that the service should be restarted after installation. The advisory revision history shows republication and later updates, including removal of a Belgium fix link on 2026-03-10 and again on 2026-03-17. Supplied enrichment marks the issue as not KEV-listed.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-13844 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-13844

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-13844 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13844

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.